Home Blog Page 194

From Data Breach to Darknet: Hackers Trade Over 15 Bn Stolen Credentials

From Data Breach to Darknet

Security experts from risk protection solutions provider Digital Shadows found threat actors trading more than 15 billion usernames and passwords, including over 5 billion unique credentials on various hacking forums.

In its security investigation study, “From Exposure to Takeover,” Digital Shadows explained how cybercriminals exploit users’ stolen credentials to bank accounts, social media handles, and video streaming services to their advantage. The number of stolen and exposed credentials has increased to 300% from 2018 from more than 100,000 data breach incidents.

While most of the account details are made available on the dark web for free, the average amount that hackers trade on account is $15.43. The survey also highlighted that bank and financial account credentials are the most expensive commodities on the darknet, averaging from $70.91 to $500, depending on the quality of the account. The researchers also observed the growth of “account takeover as-a-service,” in which cybercriminals prefer renting a credential or fingerprint data like cookies and IP addresses for some period for less than $10,  than buying it. Hackers also use dark web marketplaces to discuss various techniques on how to bypass two-factor authentication.

Image Source: Digital Shadows

“Usernames with invoice or invoices were by far the most common advertised and comprise 66% of the 2 million usernames assessed. Partners and payments came in a distant second and third place, both with 10% each. Dozens of advertisements for domain admin access are also advertised, and in many cases, are being auctioned to the highest bidder with prices ranging from $500 to $120,000 – on an average $3,139. Digital Shadows cannot confirm the validity of the data that the vendors purport to own, but listings included those for large corporations and government organizations in multiple countries,” the report said.

Mitigation Measures

Researchers at Digital Shadows advised organizations to adopt certain security practices, these include:

  • Monitor for leaked credentials of your customers, allowing you to take a more proactive response. Consider alerting your customers that their email has been involved in a breach, prompting them to reset their password if they have reused credentials
  • Deploy an online Web Application Firewall. Commercial and open source web application firewalls can be used to identify and block credential stuffing attacks
  • Increase user awareness. Educate your staff and consumers about the dangers of using corporate email addresses for personal accounts, as well as reusing passwords
  • Keep an eye on the development of credential stuffing tools and monitor how your security solutions can protect against evolving capabilities. Some credential stuffing tools are able to bypass some CAPTCHAs, for example
  • Some element of 2FA is always better than none but try to phase out multi-factor authentication using SMS. This can help to reduce account takeovers, but make sure this is balanced against the friction (and cost) it can cause

 

TikTok TikTok: The Clock’s Ticking for Chinese Video-Sharing App in U.S.

TikTok, TikTok data privacy, TikTok children's privacy

The situation for China-based social media company TikTok seems to be getting grim by the day as the U.S. Secretary of State, Mike Pompeo has already made it clear that the country is “looking at” options to ban TikTok and other such social media apps. The populous video-sharing platform had earlier been jolted in the month of May when a group of privacy and children’s welfare advocates filed a complaint against it alleging violation of children’s privacy. Sources now say that Federal Trade Commission (FTC) and the U.S. Department of Justice (DOJ) are now looking into it rather seriously.

The complainant group, which was led by Campaign for a Commercial-Free Childhood and The Center for Digital Democracy, stated that TikTok had disregarded an agreement which it made in 2019 with the FTC. As per the agreement, TikTok had promised to remove all previously uploaded content by children under the age of 13 and implement stricter parental controls and consent when collecting children’s personal data.

However, the complainants said, “We found that TikTok currently has many regular account holders who are under age 13, and many of them still have videos of themselves that were uploaded as far back as 2016, years prior to the consent decree”

Not the First Time

This is definitely not the first time that TikTok has found itself in hot waters, as in February 2020, the company settled with the FTC by agreeing to pay a $5.7 million fine for failing to adhere to the Children’s Online Privacy Protection Act (COPPA). Back then, this was the largest civil penalty ever obtained by FTC in a children’s privacy case.

The U.S. citizens have also repeatedly raised concerns over TikTok’s handling of user data. They are constantly worried about Chinese government meddling with companies by collecting their data through various online platforms and using it against them in future. TikTok, however, has always maintained that data collected from the U.S. nationals is always stored in the country itself and a backup is kept safely in Singapore where Chinese laws are not applicable.

With the mounting geopolitical tensions between the two nations, it is interesting to see whether TikTok will be slapped with another fine or eventually be pushed out of the country with a ban as the Secretary of State suggested.

USB-Borne Malware Risks See a Twofold Increase Over 12 Months

BadUSB attack

A research from technology firm Honeywell revealed that the severity of USB threats to operational technology (OT) systems doubled over a 12-month period, with the number of threats capable of disrupting OT systems rose from 26% to 59%.

The research, “Honeywell Industrial USB Threat Report,” stated that the total number of threats posed by USB removable media to industrial process control networks remains high, with 45% of locations detecting at least one inbound threat. The number of threats specifically targeting OT systems increased from 16% to 28%.

The research also highlighted that 1 in 5 of all threats was designed to leverage USB removable media as an attack vector, and more than 50% of threats were intended to act as open backdoors, establish persistent remote access, or download additional malicious payloads.

Eric Knapp, Director of Cybersecurity Research and Engineering Fellow at Honeywell, said, “USB-borne malware continues to be a major risk for industrial operators. What is surprising is that we are seeing a much higher density of significant threats that are more targeted and more dangerous. This isn’t a case of accidental exposure to viruses through USB – it’s a trend of using removable media as part of more deliberate and coordinated attacks.”

Cyberattacks via USB Drives

The risk of USB-related cyberattacks on organizations has increased exponentially. Recently, a cybercriminal gang “FIN7 APT” launched  social engineering attacks using USB drives. According to the security firm Trustwave Spider Lab, attackers posed as Best Buy officials mailed letters via postal service to the targeted victims, which contained a gift card and USB drive. The matter in the letter contained a socially engineered message intended to lure the recipients to place the USB drive on their computer. The USB drive was programmed to emulate a USB keyboard. Once victims insert the drive,  a payload is injected and a malware payload is downloaded. An additional JavaScript is also downloaded to register the infected device with the command-and-control (C2) server, which later sends encoded data containing the info-stealing software.

 

7 in 10 Organizations Suffer Public Cloud Security Breach

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

A cloud security survey by cybersecurity firm Sophos revealed that 70% of organizations suffered at least one public cloud security breach in 2019, including other security incidents like ransomware attacks (50%), compromised accounts (25%), exposed data (29%), and cryptojacking (17%).

The survey report titled “The State of Cloud Security 2020” stated that 50% of organizations that use multi-cloud environments are more likely to suffer a cloud security incident than those using a single cloud. Organizations in Europe were less affected by cloud security incidents due to the region’s existing GDPR law. While in India, nearly 93% of organizations were hit by an attack in the last year.

Misconfigurations Increase the Risks

Inadvertent database exposure continues to be a major risk for organizations, with misconfigurations exploited in 66% of reported attacks. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only 1 in 4 respondents stated lack of staff expertise as a top concern.

Chester Wisniewski, the Principal Research Scientist at Sophos, said, “Ransomware, not surprisingly, is one of the most widely reported cybercrimes in the public cloud. The most successful ransomware attacks ​​include data in the public cloud and attackers are shifting their methods to target cloud environments that ​ cripple necessary infrastructure and increase the likelihood of payment. The recent increase in remote working provides extra motivation to ​disable cloud infrastructure that is being relied on more than ever, so it is worrisome that many organizations still don’t understand their responsibility in securing cloud data and workloads. Cloud security is a shared responsibility, and organizations need to carefully manage and monitor cloud environments in order to stay one step ahead of determined attackers.”

The survey findings are based on the responses from more than 3,500 IT managers across 26 countries in Europe, the Americas, Asia Pacific, the Middle East, and Africa that currently host data and workloads in the public cloud.

Cloud Security Risks on Rise

A similar survey, “State of Cloud Security,” conducted by Fugue revealed that IT and cloud security professionals are concerned about the security of their cloud environments as several organizations working remotely. The survey found that 96% of cloud engineering teams are at present 100% working from home, while 83% of them completed the transition or are still in the process. It also found that 84% (who are making the shift) are concerned about security vulnerabilities created during the swift adoption of new access policies, networks, and devices used for managing cloud infrastructure remotely. The survey stressed that preventing cloud misconfiguration remains a challenge for cloud engineering and security teams, with 73% of them citing more than 10 incidents per day, 36% experiencing more than 100 per day, and 10% suffering more than 500 per day.

 

Surge in Cyberattacks Leaves Economic Impact on U.S. State and Local Governments

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

A survey report from KnowBe4, a provider of security awareness training for social engineering, spear phishing and ransomware attacks, revealed that rising ransomware attacks on municipalities continue to impact state and local governments across the U.S.

In its report “The Economic Impact of Cyberattacks on Municipalities”, KnowBe4 stated that ransomware attacks are becoming a costly affair, and the ransom paid per event in municipalities from 2017 to 2020 was $125,6971.  Ransomware attacks not only leave a financial impact, but also result in break of trust and confidence of citizens and stakeholders. The survey broke down the economic impact into five target areas: the average financial loss from state and local governments, the denial of service to citizens due to financial loss, the frequency and the risk of recurring attacks, the challenge of allocating capital to prevent attacks, and the decline of economic investment in municipalities.

Other findings from the survey report include:

  • Ransomware attacks can cause significant downtime and denial of critical community services, such as healthcare and law enforcement. The analysis revealed that the average downtime that results from a ransomware attack is 9.6 days.
  • Attacks on local government have risen significantly. In the single year between 2018 and 2019, known attacks on local governments rose 58.5%.
  • Government officials’ awareness level of the need for cybersecurity is low. 48% of elected councilors and/or commissioners are either slightly aware or do not know the extent of the need for cybersecurity measures in the community.

A lack of understanding exists for how cyberattacks occur and how to mitigate them. 53.3% of local government institutions do not keep track of their cyberattacks. Stu Sjouwerman, CEO, KnowBe4, said, “State and local government entities are often operating on tight budgets and cannot afford to be hit with ransomware. We have found that municipalities are struggling to keep up with the barrage of frequent cyberattacks and although significant, the impact goes beyond financial implications. Critical services such as health care and law enforcement would be put in a very difficult situation if their services went down for any period of time, which is why it’s so important to train all employees, especially those working in municipalities, to help prevent cyberattacks.”

Lack of funding for cybersecurity initiatives is a pressing issue because without initiatives like cybersecurity awareness training, municipalities are vulnerable to social engineering attacks – which in turn could expose an entire database of sensitive information to threat actors.

 

Curtains down on CISO MAG’s Middle East CISO Forum

ME Forum

The Middle East region has often been quick to embrace emerging technologies and comprehensive countermeasures to fortify its cybersecurity prowess. The scenario was not very different even during the time of the COVID-19 pandemic. With the heightened need for Work from Home protocols, vulnerabilities in the remote-working space also increased manifold. To address the cyberthreats emerging from several newer vectors and to bring several thought leaders and cybersecurity stalwarts together to discuss the new normal, CISO MAG recently hosted the Middle East CISO Forum. Unlike the earlier CISO MAG’s Middle East CISO Summits, this event took a virtual format to create awareness on the need for cybersecurity and its related implications  in the times of a pandemic.

The Middle East CISO Forum also brought forth a dynamic mix of senior cybersecurity experts to deliver real insights on how to redefine security frameworks and efficiently mitigate cyberthreats to an audience comprising of CEOs, CIOs, CTOs, CSOs, CISOs, CDOs, SVP, VP, Directors, IT Security Advisors, Ethical Hackers, Head of Planning, Governance, Risk, Head of SCADA, Head of Automation, Smart Grids, Digital Oilfields, ICT, IT Auditors, Information Security Managers and IT Consultants from several countries across the world.

The Forum began with a special address by Dr. Sohail Munir, Advisor – Emerging Technologies and Digital Innovation, Smart Dubai Government on AI, Blockchain, Cloud – Cyberthreats, and opportunities. Sohail Munir is the Advisor for Emerging Technologies and Digital Transformation at Smart Dubai Government. He is a seasoned industry professional with over  23 years of Program Management experience in the space of GovTech, Smart City, Safe City, Digital Transformation, Digital ID, C4I Systems, and FinTech. Munir’s current R&D interests are in the space of Digital Government Transformation using Blockchain, IoT, Cloud Computing, Software Defined Networking, Data Analytics, AI, and Machine Learning.  In his address,a he stressed on three key areas to leverage AI, Blockchain, and Cloud. These include: Protect AI-powered systems:  Secure AI training data, training pipelines and ML models; AI to enhance cybersecurity defense: Use ML to understand patterns, uncover attacks and automate aspects of cybersecurity processes, while augmenting the actions of human security analysts; and Adversarial AI: Identifying attacks and defending against them will be an important addition to the cybersecurity role.

This was followed by a technical address by Dr. Moataz Binali, Vice President, Trend Micro, Middle East & North Africa, which focused on Securing the Digital Transformation for MENA Region. In his address, he stressed on how 2 out top 5 biggest risks to businesses in MENA are cybersecurity-related. He also highlighted global practices to implement a cybersecurity strategy fit for digital transformation. These included Connected Threat Defense, Hybrid Cloud Security, XDR (anything detection & response), XGEN (cross generational threat defense), and Virtual Patching. As Vice President for Trend Micro Middle East and North Africa (MENA), Dr. Binali is responsible for spearheading the company’s strategy across the region, and advancing its position as a leader in cybersecurity that is passionate to make the world safe for exchanging digital information.

The following technical address was by Ray Kafity, Vice President, Middle East Turkey and Africa (META), Attivo Networks. Kafity possesses rich experience in sales and marketing management of high-tech solutions. He also has an extensive industry experience in broadband telecommunications, internet acceleration through caching appliances, internet/web content security networks, and application acceleration, and various cybersecurity prevention and detection solutions. His address focused on Cyber Deception & MITRE ATT&CK Framework for Advanced Cyber Threat Detection and Response. 

It was followed by a special address by Eng. Meshal Abdulla BinHussain, Information Technology Director, Ministry of Finance, UAE. His address focused on cyber threats looming in cyber space. According to him, “Current threat environments of cyber space shall revise and redefine the accurate and relevant policies and processes to Identify, investigate and thwart cyberattacks, share the intel with community and secure the computer networks. The nature of threats may not be considered as simple, but maybe targeting to inflict strategic & economic impact on entities.”  He added, “Multitude of cybercriminals are targeting computer systems as cybersecurity is changing. Cybercrime has become established and sophisticated. This makes it easier since we live in a data-driven and connected era where Big Data and the Internet of Things are increasingly leveraged across entities.” According to him, the key strategies to overcome these threat vectors include: Define a country-wide Cybersecurity Strategy with clear directions and objectives, Cover the gaps in existing legislation to ensure judicial support, Involvement of top management of Entities in Cyber Defense, and Create an authorized Community of Cyber Security Professionals & Entities against Cyber Attack by governing authorities.

 BinHussain’s session was followed by a technical address by Rani Hmayssi, Regional Manager, Google Cloud MENA, in which he spoke on Cloud Security for the Modern CISO. He followed a timeline of event starting from the outbreak of the Coronavirus, its effect on consumers around the world, the plummeting stock market, and the increased remote working scenarios. He went on to differentiate between the new normal which can both be an obstacle and an accelerator. He also stressed on how Google Cloud has been an enabler for WFH. He also spoke on the zero-trust model as well as methods for solving security data overload. Hmayssi currently leads Google Cloud’s security presence in the Middle East and helps organizations achieve their digital transformation objectives using Cloud and AI.

The session was followed by the highlight of the Forum, which was the Panel discussion on Addressing New Cybersecurity Blind Spots – Leveraging AI and ML. The session was moderated by Dr. Erdal Ozkaya, Managing Director & Regional CISO, Standard Chartered Bank (UAE). The panelists of the discussion were Sultan Altukhaim, Director, Information Security Department (CISO), Risk Management, Capital Market Authority; Abdullah Biary, CISO, Salama Cooperative Insurance Company; Thomas Heuckeroth, Group Cybersecurity Lead, Emirates Group; and Majd Sinan, Trend Micro Country Manager, UAE.

Following the first panel discussion, Mariana Pereira, Director of Email Security Products EMEA, Darktrace took a technical session on Faking It: Combatting Email Impersonation with AI. As the Director of Email Security Products at Darktrace, her primary focus lies on the capabilities of AI cyber defenses against email-borne attacks. Pereira works closely with the development, analyst, and marketing teams to advise technical and non-technical audiences on how best to augment cyber resilience within the email domain, and how to implement AI technology as a means of defense.

Pereira’s session was followed by the last panel discussion on the topic, Cybersecurity as a Transformation Enabler in an Era of Hyper Connectivity and Cloud. The discussion was moderated by Piyush Kumar Chowhan, Group CIO, Lulu International, and the panelists were  Ali Abdulla Alsadadi, Head of IT, National Oil and Gas Authority (Bahrain); Mohamed Saad Mousa, Chief Information Security Officer, Ikea; Mariana Pereira, Director of Email Security Products EMEA, Darktrace; Mohannad Alkalash, Founder, CyberX; and Piergiorgio Di Giacomo, Chronicle Security Lead, Google Cloud in participation.

All the sessions and panel discussions were followed by a live Q&A with the audience. You can watch the entire recording of the Middle East CISO Forum at https://attendee.gotowebinar.com/recording/3725001766794837774

 The title sponsor of the Middle East CISO Forum was Trend Micro. Other sponsors of the Forum include Attivo Networks (Platinum Partner), Google Cloud (Gold Partner), Dark Trace (Gold Partner), and CyberX (Silver Partner). The media partners of the event were CXO Insight (Middle East) and UAEBusiness.com.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. Learn more at https://www.eccouncil.org.

Bolstering Cybersecurity Posture with Red, Blue and Purple Teams

red and blue teaming

Post the COVID-19 outbreak, organizations worldwide need to revisit their existing business model and bring in radical changes into the ongoing business operations by streamlining the various business processes and the underlying technology stack that will support the business operations. COVID-19 has made most of the global organizations to start working from home with the help of remote connection capabilities established in place. Such situations may continue very well even after the crisis get over. Because across the globe, organizations have a view that working from home kind of approaches give significant cost savings and productivity improvement. But the other side of such new approach will increase the cyberthreat landscape of the organizations, which is revealed by the recently emerging cyberthreats targeting remote workers.

By Vimal Mani, Head of Information & Cyber Security Operations of Bank of Sharjah

New methods and techniques need to be considered for implementation for bolstering the cybersecurity posture of organizations globally. There are many new techniques being explored for strengthening cybersecurity posture such as Zero Trust, Defence in Depth and others. In the same line, several global organizations have started building Red Teams, Blue Teams and Purple Teams as part of their Cybersecurity Capability Development.

What are Red, Blue and Purple Teams?

Red and Blue Teams are generally exercises carried out by military forces to mimic an enemy and his attack techniques and device counterattack techniques to prevent the attacks from enemy. This Red Team approach is being adopted by contemporary business organizations globally to device fool proof business strategies that will help them in winning over their competition.

In recent past, global organizations have started embracing the Red and Blue Team approaches for bolstering their cybersecurity capabilities for addressing the dynamically emerging cyberthreats from adversaries. Organizations conduct Red Teaming engagements through external consultants as well develop their own internal Red Teams.

What are Red Teaming Engagements?

Red Team engagements are full-fledged cybersecurity assessments in which consultants wear the hats of adversaries and try emulating real life cyberattack scenarios on the client organizations based on mutual agreements. This helps organizations in identifying the gaps, weakness, and single point of failures in the enterprise wide security architecture. The consultants use logical, physical, and social engineering attack techniques used by real hackers in the industry. But these attack vectors get customized inline to the agreement signed with the organizations, which will have defined boundaries for these Red Teaming engagements.

The following types of attacks may be emulated during the Red Teaming engagements:

  • Physical Attacks
  • Internal Network Penetration Attacks
  • External Network Penetration Attacks
  • Social Engineering (Phishing, Vishing, Smishing etc.)
  • Wireless Network Penetration Attacks
  • Pivoting
  • Achievement of goals agreed (Data Exfiltration etc.)

Who are Blue Team Members?

Generally an organisation’s in house IT Security & SOC Team members who fight against cyberattacks are considered as Blue Team Members. Blue Team members need to ensure that the critical information assets owned by the organization are secured from various kinds of attacks that may be targeted on them by adversaries and Red Team members who mimic the adversaries. Also the Blue Team Members need to handle the complete cycle of incident management which will be led by SOC team from the front. The following list of activities are performed by Blue Team members:

  • Vulnerability Analysis
  • Patch Management
  • Internal Penetration Testing
  • System Hardening
  • Implementation of Security Baselines
  • Configuration Reviews & Changes Implementation
  • Compliance Reviews
  • Log Monitoring
  • Incident Analysis (Triaging)
  • Remediation Planning & Implementation

Who are Purple Team Members?

Purple Teaming is a newly emerging concept in cybersecurity. Purple Team is a team of cybersecurity professionals playing both the roles of Red Team & Blue Team in ongoing and integrated manner for providing much reliable cyber assurance for organizations who employ them. As a Red Team, they will collect the intelligence on Tactics, Techniques and Procedures (TTPs) used by adversaries. Then as a Blue Team, they will analyse these TTPs and configure, tune, and improve the incident detection and response capability of the organisations who employ them. Another example is, as a Red Team, they can send out phishing emails to staff and as a Blue Team they can conduct structured security awareness trainings to staff. This Purple Team may not be a separate team and they will be the individuals who are part of an organisations existing Cybersecurity Team and their job is to maximize the effectiveness of their team in preventing the incidents in a timely manner.

Conclusion

Leveraging the capabilities of Red/Blue/Purple Teams in an integrated manner is need of the hour for organizations globally. It provides great opportunities towards bolstering and improving the cybersecurity posture of organisations. Development of Red/Blue/Purple Team capabilities and integrating them in a seamless manner should be considered as one of the critical action items planned by Information & Cybersecurity Teams in an organization every year. Using these Red/Blue/Purple Teams in an integrated manner will help an organisation in improving its incident management capabilities and introducing state of the art cybersecurity skills, solutions and improving the overall cybersecurity posture of the organization.

About the Author

Vimal ManiVimal Mani, CISA, CISM, Six Sigma Black Belt, is the Head of Information & Cyber Security Operations of Bank of Sharjah. He is responsible for the bank’s information & cybersecurity programs, coordinating security operations spread across the branches in Middle East. Mani is also responsible for coordinating bank wide security strategy and standards, leading periodic security risk assessment efforts, incidents investigation and resolution and coordinating the bank’s security awareness and training programs.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Cerberus – A Banking Trojan Disguised as Currency Converter

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

Researchers from Avast discovered a malicious Android app “Cerberus” on the Google Play store spreading a banking Trojan. The Trojan was being spread via a Spanish currency converter app “Calculadora de Moneda” targeting Android users in Spain since March 2020, with 10,000 downloads already. The researchers stated that Cerberus Trojan, if downloaded, can steal banking credentials, bypass security measures, access text messages, and even alter two-factor authentication (2FA).

“As is common with banking malware, Cerberus disguised itself as a genuine app in order to access the banking details of unsuspecting users. What is not so common is that a banking Trojan managed to sneak onto the Google Play Store. To avoid initial detection, the app hid its malicious intentions for the first few weeks while being available on Google Play. During this time, the app acted normally as a legitimate converter, and it does not steal any data or cause any harm. This was possibly to stealthily acquire users before starting any malicious activities, which could have grabbed the attention of malware researchers or Google’s Play Protect team,” the researchers said in a statement.

The Cerberus Trojan app operates stealthily to gain the trust of users and steals their banking data later. The app executes itself in three different stages:

  • In the first stage, the Calculadora de Moneda app appears normal and does not steal any data from users who have downloaded it.
  • In the second stage, the normal looking app turns into a malicious dropper, which is intended to download another malicious app onto a device, without the user’s knowledge.
  • In the final stage, the app activates the malicious Trojan to access the existing genuine banking app on the victim’s device and wait for the user to log in. The Trojan creates a layover on the login screen to capture the credentials.

Avast stated that the malicious app has been taken down after it reported the findings to Google.

Protection Against Banking Trojans

Avast recommended users certain mitigation measures to protect themselves from mobile banking Trojans, these include:

  • Confirm that the app you are using is a verified banking app. If the interface looks unfamiliar or odd, double-check with the bank’s customer service team.
  • Use two-factor authentication if your bank offers it as an option.
  • Only rely on trusted app stores, such as Google Play or Apple’s App Store. Even though the malware slipped into Google Play, its payload was downloaded from an external source. If you deactivate the option to download apps from other sources, you will be safe from this type of banking Trojan activating on your phone.
  • Before downloading a new app, check its user ratings. If other users are complaining about a bad user experience, it might be an app to avoid.
  • Pay attention to the permissions an app requests. If you feel that the app is requesting more than it promises to deliver, treat this as a red flag.
  • Often, malware will ask to become a device administrator to get control over your device. Don’t give this permission to an app unless you know this really is necessary for an app to work.

Not the First Time

In 2019, Kaspersky discovered the Ginp Banking Trojan, which lures Android users to steal their credit card credentials.

For more information, read, “Ginp Banking Trojan Lures Android Users Amidst COVID-19 Outbreak

 

 

Cybercrimes in U.K. Doubled Since 2015, Costing Businesses $108 Bn

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

Research from business ISP provider Beaming revealed that the number of businesses in the U.K. that affected by cyberattacks has doubled since 2015. The five-year cybersecurity research stated that 1.5 million businesses (25%) in the U.K. suffered cyberthreats in 2019, compared to 755,000 businesses (13%) in 2015, costing them £87 billion (US$ 108 billion).

The research also highlighted that large-scale businesses were the most affected, with 9 in 10 companies (87%)  reporting cyberattacks. Small and Medium Businesses (SMBs) have seen the steepest rise in attacks, compared to 28% of firms hit in 2015, to 62% in 2019.

Image Source: Beaming

Other Notable Findings from Beaming’s Study include:

  • Over the past five years larger companies were consistently breached at a higher rate than smaller businesses. The risk of becoming a victim increases by more than 60% when a company hires its first employees.
  • Although more companies are taking measures against cybercrimes, uptake of these measures remains very low overall. In 2015, 5% of businesses had a cybersecurity policy; that figure is now 9%. In 2015, 30% of businesses had a firewall at the network perimeter; that figure is now 37%. In 2015, 20% of businesses put in place employee training and awareness-raising measures; that figure is now 22%.
  • More than a fifth of small (20%), medium (24%) and large companies (36%) now discuss a range of cyberthreats at the board level. The proportion of businesses taking additional steps to mitigate a range of cyber-risks has increased from 16% in 2015 to 37% last year.
  • Malware continues to be the biggest concern for business leaders, with 45% of them taking additional measures to combat it (compared to 26% in 2015).
  • In 2019, Phishing was the most common form of successful attack on every size of business – with the exception of micro companies, where 1% more fell victim to malware (although in 2018 phishing was also by far the biggest threat to micros too). The proportion of businesses hit by phishing attacks grew by 50% in five years, from 6% in 2015 to 9% in 2019.
  • Staff members were responsible – either through malicious intent, neglect, or genuine mistakes – for breaches in more than a third of cases. Business leaders held employees accountable for 37% of breaches in 2015, and 36% in 2019.
  • Beaming’s research indicates that almost two-thirds (61%) of U.K. businesses have minimal levels of cybersecurity defenses in place, relying on anti-virus software and basic router protection to keep them safe. 69% of micro businesses and 58% of small companies were in this situation at the start of 2020.

Sonia Blizzard, Managing Director of Beaming, said, “Cybercrime is one of the first fields to embrace automation, allowing hackers to launch increasingly sophisticated attacks with unprecedented scale and frequency. Businesses of all sizes need to think hard about improving the resilience of their IT and communication systems, to minimize the chances of being breached and the potential impact.”

She added: “The threat has grown astronomically over the last five years. What used to be seen as a big-business problem has become a serious concern for every company director, manager, and IT professional out there. Small businesses are now on the front line in the war against cybercrime. But they have not invested in cybersecurity or employee education at the same rate as their larger counterparts, and they are easier targets as a result.”

 

Deloitte Prescribes 5-Step Security Approach to Protect Enterprises and WFH Employees

Remote Work

With no end in sight to COVID-19, organizations have now accepted work from home (WFH) as the new normal. In fact, many Indian companies took a decision recently to let a section of their workforce to work from home permanently. This has been well accepted by millennials and Gen Z workers, according to a survey by Deloitte. But there are myriad cybersecurity challenges faced during the pandemic.

Deloitte’s 9th Global Millennial Survey 2020 stated cybersecurity to be a top concern amongst Indian millennials, which is a clear reflection of a number of cyberattacks that have been witnessed on MNCs operating in India, in the past week alone.

The survey further states that 86% of millennials and 83% of Gen Zs agreed they prefer the option to work from home in the future, to relieve stress.

With work from home (WFH) becoming the “new normal” amidst the COVID-19 crisis and cyber attackers and virus lurking in the shadows, enterprises can adopt a  five-step approach to reassess their exposure to cyber challenges and secure their enterprises, as per a Deloitte perspective.

The five-step approach includes:

  1. Implement multi-factor authentication: Organizations should enable multi-factor authentication (MFA) across all internet-accessible remote access services including Web and cloud-based email, Collaboration platforms, Virtual private network (VPN) connections and Remote desktop services.
  1. Implement an ongoing cyber threat education and awareness program for organizational users: Educate users on current threats, the dangers of opening attachments or clicking links from untrusted sources, and the basic actions needed to prevent infection. It is essential to educate users to be wary of unexpected email messages, and to authenticate them with their ostensible senders before opening any links or attachments within them.
  1. Know your most critical data and systems and where they are located: Not all data and systems are of the same value to organizations and attackers. Knowing the ‘what’ and ‘where’ of critical data and systems allows you to target resources on your most important assets first. Critical data and systems can be overlooked, especially when trying to protect everything in an organization. Ensure critical data is backed up and systems are recoverable.
  1. Update your patching regularly: Internet-facing infrastructure is a primary target for attackers. By patching this infrastructure, you can help prevent attackers from exploiting known vulnerabilities in the software in order to gain access to your network and systems. It is recommended to apply patches within 48 hours of release.
  1. Monitor and analyze activity on your most critical systems: A critical component of protecting your environment is to understand what is happening in real-time. Without this visibility and what has already happened to your systems and data, you are effectively operating blind.

Speaking on the recent cyberattacks, Shree Parthasarathy, Partner and National Leader – Cyber Risk Services, Deloitte India, said, ”In the era dominated by digital transformation, Indian enterprises have been susceptible to some major cyber-attacks and threats as a result of businesses transitioning to cloud with broader networking capabilities.”

While these threats are not new, their sophistication and frequency have increased and there is an immediate need for businesses to draw a crisis management and resiliency plan of action.

“A robust and consistent layer of identity and access management built with a multi-factor authentication and encryption policy will help in aligning a thoughtful cybersecurity policy to overcome the dual crisis hovering over the country,” he added.